Active Directory User Group and Rights Management SOP
Purpose
Control AD users, groups, delegation and privileged rights throughout the account lifecycle.
Decision Summary
Avoid direct per-user ACLs. Protect privileged/operator groups and alert on membership changes.
Use Cases
Onboarding, transfers, offboarding, security groups, OU delegation and service accounts.
Hardware Requirements
Supported server, secure management path, current backup and adequate workload capacity.
Backup Strategy
Export permissions and back up configuration/application data before material changes.
Recovery Strategy
Use approved break-glass access or restore known-good configuration; revoke unintended access and validate.
Secure Boot Notes
Keep Secure Boot enabled where supported; access administration does not require disabling it.
Version History
v1.0 — 2026-08-04 — Initial controlled SOP.
Technology Register Metadata
- CSI Classification: Production Ready
- CSI Tech ID: 147
- Category: Field SOPs
- Client Approved: No
- Commercial Use: Allowed
- Current Version: 1.0 — 2026-08-04
- Documentation URL: https://learn.microsoft.com/windows-server/identity/ad-ds/manage/understand-security-groups
- Evidence Complete: Yes
- Last Updated: August 4, 2026 3:16 AM
- Licence: CSI Internal SOP — underlying product licence terms apply.
- Lifecycle Status: Done
- Risk Flag: High Risk
- Ventoy Compatibility: Not Applicable
Migration Record
Imported deterministically from the CSI Technology Register.
Source classifications, approval state, risk state, version information and testing status have been preserved. No additional approval or validation has been inferred during migration.
Cyber Space Infocom
Making Technology Work for You